¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180703
Ðû²¼Ê±¼ä 2018-07-03¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯
PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬£¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÐµÄDiameterµç»°ÐÒéÓëSS7Ò»ÑùÒ×Êܹ¥»÷
Çå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä±ê×¼Ò»ÆðʹÓõÄDiameterÐÒéÈÝÒ×Êܵ½Óë¾ÉµÄµç»°±ê×¼£¨Èç3G£¬£¬£¬£¬£¬£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7±ê×¼ÏàͬÀàÐ͵ÄÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬£¬SS7ÊÇÔÚ20ÊÀ¼Í70ÄêÔ¿ª·¢µÄ£¬£¬£¬£¬£¬£¬¿ìÒª¶þÊ®Äê֤ʵÆä±£´æ²»Çå¾²ÒòËØ¡£¡£¡£¡£¡£ÕýÓÉÓÚÔÆÔÆ£¬£¬£¬£¬£¬£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂç×îÏÈ£¬£¬£¬£¬£¬£¬SS7±»DiameterÐÒéËùÈ¡´ú£¬£¬£¬£¬£¬£¬DiameterÐÒéÊÇÒ»ÖÖˢеÄÍø¼äºÍÍøÄÚÐÅÁîÐÒ飬£¬£¬£¬£¬£¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G±ê×¼¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/
¡¾Çå¾²²¥±¨¡¿ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼
ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬£¬£¬£¬£¬£¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£¡£¡£¡£Ô×ÓÄÜ»ú¹¹ÌåÏÖ£¬£¬£¬£¬£¬£¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅЧÀÍÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬£¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬£¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/
¡¾Çå¾²²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ
FacebookÒѾÈϿɣ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬£¬£¬£¬£¬£¬FacebookÌåÏÖ£¬£¬£¬£¬£¬£¬ËüÒѾÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£¡£¡£¡£¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html
¡¾Çå¾²²¥±¨¡¿ÈýÐDz¿·ÖϵÁÐÊÖ»ú±£´æbug£¬£¬£¬£¬£¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË
×îа汾µÄÈýÐǶÌÐŶÌÐÅÓ¦ÓóÌÐò±£´æbug£¬£¬£¬£¬£¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬£¬£¬£¬£¬£¬ÈçS9¡¢S9 PlusºÍNote 8£¬£¬£¬£¬£¬£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£¡£¡£¡£¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬Óöµ½bugµÄÓû§Ëµ£¬£¬£¬£¬£¬£¬ËûÃDz»ÖªµÀÊÖ»úÒѾ·¢ËÍÁËÕÕÆ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£¡£¡£¡£¡£Ö»Óе±ÕâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬£¬£¬£¬£¬£¬ËûÃDzŷ¢Ã÷¡£¡£¡£¡£¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÓ¦ÓóÌÐòÖ±µ½ÈýÐÇÐÞ¸´ÕâЩÎÊÌâ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/
¡¾Îó²î²¹¶¡¡¿VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄÎó²î
VMwareÉÏÖÜ֪ͨ¿Í»§£¬£¬£¬£¬£¬£¬ÆäÐÞ²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖзºÆð¾Ü¾øÐ§ÀÍ£¨DoS£©»òÐÅϢй¶µÄÎó²î¡£¡£¡£¡£¡£¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓÃÇå¾²Îó²î»ñÊØÐÅÏ¢»òʹÐéÄâ»úÍ߽⡣¡£¡£¡£¡£¸ÃÎó²î±»ÁÐΪÖ÷Òª£¬£¬£¬£¬£¬£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£¡£¡£¡£¡£Cisco TalosµÄÑо¿Ö°Ô±·¢Ã÷ÁËCVE-2018-6965¡£¡£¡£¡£¡£¾ÝVMware³ÆÕâЩȱÏÝ»áÓ°ÏìÔÚÈÎºÎÆ½Ì¨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬£¬£¬£¬£¬£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬£¬£¬£¬£¬£¬²¢ÒÑÐû²¼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄÐÞ²¹³ÌÐòºÍ¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion


¾©¹«Íø°²±¸11010802024551ºÅ